Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5841

Опубликовано: 01 фев. 2024
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
Версия до 3.2.1 (включая)

EPSS

Процентиль: 70%
0.00655
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 1 года назад

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

CVSS3: 9.1
redhat
больше 1 года назад

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

CVSS3: 9.1
debian
больше 1 года назад

Due to a failure in validating the number of scanline samples of a Ope ...

rocky
9 месяцев назад

Important: openexr security update

rocky
9 месяцев назад

Important: openexr security update

EPSS

Процентиль: 70%
0.00655
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-122
CWE-787